HumHub logo

HumHub

Open-source private social network and collaboration platform

Alternative to: Facebook Workplace, Yammer, Nextdoor


About Versions (106)

v1.19.0-beta.3

2026-09-22

This release also fixes security issues.

  • Fix #8414: A grouped activity named the same user twice when they had several activities in the group, and named nobody at all when the group’s only other participant was the reader
  • Fix #8417: Top menu keeps the previous entry highlighted after a pjax navigation (since 1.19.0-beta.1)
  • Fix #8412: Applying a UI addition by its id did nothing when it was registered without a selector, and additions.extend() with applyOnInit threw instead of applying
  • Enh #8411: Removed the AssetBundle::$defaultDepends mechanism — a property-name typo kept it from ever running, and activating it makes the core bundle depend on itself, see docs/develop/module-migrate.md
  • Fix #8401: Module version migration crash when module versions cannot be determined
  • Fix #8400: Button text horizontal centering and spacing in People heading (since 1.19.0-beta.2)
  • Fix #8404: Remove deprecated function curl_close()
  • Fix #8410: Select2 library is loaded twice by the browser
  • Fix #8415: A user picker or space picker request without a keyword parameter crashes with a TypeError
  • Enh #8416: Auto-focus the newly loaded content after a pjax swap, so Tab no longer restarts at the top of the page
  • Enh #8419: Add a space between at the top of the card icons (in the card header)
  • Fix #8418: Replace the leftover Bootstrap 3 class pull-right with float-end in the admin basic settings and the space directory heading buttons
  • Enh #8421: Customize Bootstrap through its Sass variables in variables.scss instead of redeclaring the generated --bs-* CSS variables in the component SCSS files (buttons, badges, dropdowns, list groups, navs, popovers, progress bars, tables and tooltips)
  • Fix #8422: Replace removed .sr-only class with .visually-hidden
  • Fix #8434: Badge::action() and Badge::withLink() rendered the badge markup escaped inside the link, since the wrapping link encoded the label it is given in Badge::run() — which is the already rendered badge, not text
  • Enh #8425: Implement visible focus for elements in cards for keyboard accessibility
  • Fix #8269: File-handler dropdown menu items had no href, so they were skipped by Tab and could not be focused via keyboard or the dropdown’s arrow-key navigation
  • Fix #8423: Fix tab order of the reset filters button in the search area
  • Fix #8438: Endless scrolling stalled whenever the loaded stream entries did not push the stream end indicator out of the observed area (compact streams, short entries, viewport not filled), because an IntersectionObserver only reports state changes — the stream now keeps loading until the observed area is filled
  • Fix #8438: The mobile “Load more” button of a stream was hardwired to the #wallStream id, so it failed with “Handler not found” in any stream rendered with a custom id
  • Fix #8448: Destructive admin actions (remove all space members, delete profile category, reset invite link, remove licence) ran on GET via CSRF
  • Enh #8452: docs/develop/module-migrate.md is now only an index — each release line keeps its breaking changes in its own module-migrate-<version>.md, so develop and next no longer collide in a shared Unreleased section
  • Enh #8454: The core functional test suite could not run a single test — FixtureHelper::_afterSuite() unloaded fixtures against the application the Yii2 module destroys after every test, aborting the whole run; the suite also lacked the Asserts module
  • Fix #8484: The documented php yii installer/... console commands (write-db-config, install-db, write-site-config, create-admin-account, set-base-url, auto) all answered “Unknown command”: the installer module config declared no consoleControllerMap, so its command controller was never registered
  • Fix #8492: Concurrent requests could store a like on a content itself twice, inflating the like counter — the unique index on like cannot catch this, since such a like stores NULL in content_addon_record_id and MySQL/MariaDB treat NULLs in a unique index as distinct; likes on the same target are now serialized through the mutex component, re-checking after the lock
  • Enh #8408: Highlight the stream “Show more” link on focus and move focus to newly loaded entries afterward
  • Fix #8495: The “Use SMTPS” and “Allow self-signed certificates” checkboxes of the mailing settings and of the installer’s mail step ignored isFixed(), so on an instance that fixes mailerUseSmtps or mailerAllowSelfSignedCerts they stayed editable while every field around them was read-only, and a change silently did nothing because SettingsManager::set() discards writes to a fixed setting
  • Fix #8495: ConfigTest::testFixedSettings() asserted the nested HUMHUB_FIXED_SETTINGS__BASE__MAILER__* form, which still parses but yields fixed-settings['base']['mailer'][…] — not a setting name since the mailer settings were flattened in m250226_125226_rename_mailer_vars, so the test documented a form that configures nothing; it now asserts the working flat form, and the nested behaviour keeps its own test
  • Fix #8496: Retire the themes/HumHub directory the 1.19 move of the core theme (#8102) leaves behind in the webroot, and repair the theme setting when it still points at it
  • Fix #8505: Topic sidebar widget showed topics unused in the Space, and its position is now configurable